Fault detection for systems implementing a block cipher
Abstract
A fault detection method for an encryption/decryption system based on a block cipher comprises the steps of subjecting a state array (CST) to multiple rounds, each round comprising a same series of sequential operations transforming the state array; storing the state of a reference operation (ShiftRows) of a current round as a checkpoint state (CHK); storing the state of the reference operation in the next round as an intermediate state; applying one round of reciprocal operations to the intermediate state, starting from the reciprocal of the reference operation (InvShiftRows); and comparing the result state of said one round of reciprocal operations with the checkpoint state.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . An encryption circuit based on a multiple-round block cipher, comprising:
an encryption accelerator comprising, connected in a ring:
a substitute-bytes circuit,
a shift-rows circuit,
a mix-columns circuit,
an add round-key circuit,
a ciphertext register connected to store an output of the add round-key circuit at the rhythm of a round clock,
a first multiplexer connected to insert a plaintext message in the ring in a first round, at an input of the add round-key circuit;
a decryption accelerator comprising, connected in series:
an inverse shift-rows circuit,
an inverse substitute-bytes circuit,
an add round-key circuit,
an inverse mix-columns circuit, and
a plaintext register connected to store an output of the inverse mix-columns circuit at the rhythm of the round clock;
an intermediate state register connected between an output of the shift-rows circuit and an input of the inverse shift-rows circuit, and clocked by the round clock; a second multiplexer connected to select an output of the add round-key circuit of the decryption accelerator in the first round, and an output of the plaintext register in the other rounds; a third multiplexer connected to select the plaintext message in the first round and an output of the intermediate state register in the other rounds; a checkpoint state register connected to store an output of the third multiplexer at the rhythm of the round clock; and a fault-detector connected to check equality between an output of the second multiplexer and an output of the checkpoint state register.
2 . The circuit of claim 1 , wherein:
a key used by the add round-key circuit of the encryption accelerator is a key generated for a current encryption round; a key used by the add round-key circuit of the decryption accelerator is two rounds behind the key for the current encryption round; the second multiplexer operates two rounds behind the current encryption round; and the output of the checkpoint state register is delayed by one encryption round.
3 . A fault detection method for an encryption system based on a block cipher, comprising the steps of:
subjecting a state array to multiple rounds, each round comprising sequentially:
substituting bytes from the content of the state array,
shifting rows,
mixing columns,
adding a round key,
writing the add round key result in the state array; storing the state of the shifting rows operation of a current round as a checkpoint state; storing the state of the shifting rows operation in the next round as an intermediate state; applying one round of reciprocal operations to the intermediate state, starting from an inverse shifting rows operation; and comparing a result state of said one round of reciprocal operations with the checkpoint state.
4 . A fault detection method for a decryption system based on a block cipher, comprising the steps of:
subjecting a state array to multiple rounds, each round comprising sequentially:
inverse shifting rows from a content of the state array,
inverse substituting bytes,
adding a round key,
inverse mixing columns;
writing the inverse mixing columns result in the state array; storing the state of the inverse substituting bytes operation of a current round as a checkpoint state; storing the state of the inverse substituting bytes operation in the next round as an intermediate state; applying one round of reciprocal operations to the intermediate state, starting from a substituting bytes operation; and comparing a result state of said one round of reciprocal operations with the checkpoint state.
5 . The method of claim 3 , comprising the steps of:
generating and storing a reverse key from a cipher key using key expansions; applying reciprocal key expansions to the reverse key and comparing the result to the cipher key; and in each round, expanding a new round key from the cipher key and comparing the last round key to the stored key.
6 . The method of claim 4 , comprising the steps of:
generating and storing a reverse key from a cipher key using key expansions; applying reciprocal key expansions to the reverse key and comparing the result to the cipher key; and in each round, expanding a new round key from the cipher key and comparing the last round key to the stored key.Join the waitlist — get patent alerts
Track US2016315764A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.